SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 4ef2cce6edaecb12652259cdf9815b656d1da27a.

Database Entry


SHA1 Fingerprint:4ef2cce6edaecb12652259cdf9815b656d1da27a
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2018-10-18 11:50:25 UTC
Last seen:2018-10-28 11:21:30 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-28 12:43:48
Malware samples:74
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-28 11:21:305f6c89bd17765daf9a6902a9063348afn/aGozi 54.39.81.123:443
2018-10-28 11:21:305f6c89bd17765daf9a6902a9063348afn/aGozi 54.39.81.123:443
2018-10-19 06:28:0071fe52bfc6a1f08cc09fe6765d854817n/aGozi 54.39.81.123:443
2018-10-19 06:28:0071fe52bfc6a1f08cc09fe6765d854817n/aGozi 54.39.81.123:443
2018-10-19 06:24:1427c52caecb2b22d95d0e843f6759f984n/aGozi 54.39.81.123:443
2018-10-19 06:24:1427c52caecb2b22d95d0e843f6759f984n/aGozi 54.39.81.123:443
2018-10-19 06:22:53b0b0c679f20a4278445c48fa05f4dc86n/aGozi 54.39.81.123:443
2018-10-19 06:22:53b0b0c679f20a4278445c48fa05f4dc86n/aGozi 54.39.81.123:443
2018-10-19 06:22:42246c3f8c4fe7267d57e8096ada338e8bn/aGozi 54.39.81.123:443
2018-10-19 06:22:42246c3f8c4fe7267d57e8096ada338e8bn/aGozi 54.39.81.123:443
2018-10-19 06:21:3728af8831d6dc4266b74f7571e4da2ce9n/aGozi 54.39.81.123:443
2018-10-19 06:21:372c469037935323775fe2c59f96beedabn/aGozi 54.39.81.123:443
2018-10-19 06:21:3728af8831d6dc4266b74f7571e4da2ce9n/aGozi 54.39.81.123:443
2018-10-19 06:21:372c469037935323775fe2c59f96beedabn/aGozi 54.39.81.123:443
2018-10-19 06:17:469af648654ca02b53f62979a2fddb195en/aGozi 54.39.81.123:443
2018-10-19 06:17:469af648654ca02b53f62979a2fddb195en/aGozi 54.39.81.123:443
2018-10-19 06:17:113a8bc6488f480ca670ae1a2497df6e6an/aGozi 54.39.81.123:443
2018-10-19 06:17:113a8bc6488f480ca670ae1a2497df6e6an/aGozi 54.39.81.123:443
2018-10-19 06:16:50f38b80b5eb766ac37513777970fa52beVirustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-19 06:16:50f38b80b5eb766ac37513777970fa52beVirustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-19 06:09:22146ebf50aa47b6f1594641dce7556d5dn/aGozi 54.39.81.123:443
2018-10-19 06:09:22146ebf50aa47b6f1594641dce7556d5dn/aGozi 54.39.81.123:443
2018-10-19 06:07:512c46d737e4b5b8470f166a222c45bc77n/aGozi 54.39.81.123:443
2018-10-19 06:07:512c46d737e4b5b8470f166a222c45bc77n/aGozi 54.39.81.123:443
2018-10-19 06:03:087a28fd5242cddd9b782d9234ed44f78an/aGozi 54.39.81.123:443
2018-10-19 06:03:087a28fd5242cddd9b782d9234ed44f78an/aGozi 54.39.81.123:443
2018-10-19 06:02:2891fcdf224ee443911081509425a23e68n/aGozi 54.39.81.123:443
2018-10-19 06:02:2891fcdf224ee443911081509425a23e68n/aGozi 54.39.81.123:443
2018-10-19 06:02:057514dc1ef01c49c5d2e79aea312719bcn/aGozi 54.39.81.123:443
2018-10-19 06:02:057514dc1ef01c49c5d2e79aea312719bcn/aGozi 54.39.81.123:443
2018-10-19 05:58:17ff2457e8ceafe0abe9853620fa3120eeVirustotal results 35/68 (51.47%) Gozi 54.39.81.123:443
2018-10-19 05:58:17ff2457e8ceafe0abe9853620fa3120eeVirustotal results 35/68 (51.47%) Gozi 54.39.81.123:443
2018-10-19 04:38:5627bb32fc386be17fd7a328949f601897n/aGozi 54.39.81.123:443
2018-10-19 04:38:5627bb32fc386be17fd7a328949f601897n/aGozi 54.39.81.123:443
2018-10-19 04:38:07562e4ceca15b6d147d73d3deb5e5e6dfn/aGozi 54.39.81.123:443
2018-10-19 04:38:07562e4ceca15b6d147d73d3deb5e5e6dfn/aGozi 54.39.81.123:443
2018-10-19 04:32:22620215b0c467d3976d5f1af6598ad7c0n/aGozi 54.39.81.123:443
2018-10-19 04:32:22620215b0c467d3976d5f1af6598ad7c0n/aGozi 54.39.81.123:443
2018-10-19 04:32:01a005f84b374a748313a9b251a6a32748Virustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-19 04:32:01a005f84b374a748313a9b251a6a32748Virustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-19 04:30:44d5ea5e71dbf8647ec15edf5fb40a94c0Virustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-19 04:30:44d5ea5e71dbf8647ec15edf5fb40a94c0Virustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-19 04:25:29229e68e15417c328550b343e1a4bf203n/aGozi 54.39.81.123:443
2018-10-19 04:25:29229e68e15417c328550b343e1a4bf203n/aGozi 54.39.81.123:443
2018-10-19 04:14:25208dfd3f9877f4e657a7ee93d0598460n/aGozi 54.39.81.123:443
2018-10-19 04:14:25208dfd3f9877f4e657a7ee93d0598460n/aGozi 54.39.81.123:443
2018-10-19 04:14:23a3bd683e5701928d55b13eec7c9fc3e8Virustotal results 31/67 (46.27%) Gozi 54.39.81.123:443
2018-10-19 04:14:23a3bd683e5701928d55b13eec7c9fc3e8Virustotal results 31/67 (46.27%) Gozi 54.39.81.123:443
2018-10-19 04:11:3665b3ac51e3e0d93dc9b357bb539343f4n/aGozi 54.39.81.123:443
2018-10-19 04:11:3665b3ac51e3e0d93dc9b357bb539343f4n/aGozi 54.39.81.123:443
2018-10-19 04:07:39e89fc3f6d6a7b3176294e92071499e01Virustotal results 35/67 (52.24%) Gozi 54.39.81.123:443
2018-10-19 04:07:39e89fc3f6d6a7b3176294e92071499e01Virustotal results 35/67 (52.24%) Gozi 54.39.81.123:443
2018-10-19 02:47:281df077638e68b8fbb49c2defe05ddcfdn/aGozi 54.39.81.123:443
2018-10-19 02:47:281df077638e68b8fbb49c2defe05ddcfdn/aGozi 54.39.81.123:443
2018-10-19 02:43:4444cb79fa50d5a90630bba13a08319c3cn/aGozi 54.39.81.123:443
2018-10-19 02:43:4444cb79fa50d5a90630bba13a08319c3cn/aGozi 54.39.81.123:443
2018-10-19 02:40:5947a3377b861c89b157b85762ca1da8b2n/aGozi 54.39.81.123:443
2018-10-19 02:40:5947a3377b861c89b157b85762ca1da8b2n/aGozi 54.39.81.123:443
2018-10-19 02:31:5579c62fcd827ba4dae5c16e7379d0cd9en/aGozi 54.39.81.123:443
2018-10-19 02:31:5579c62fcd827ba4dae5c16e7379d0cd9en/aGozi 54.39.81.123:443
2018-10-19 02:29:57746d6830521610127645f7e7c1a126edn/aGozi 54.39.81.123:443
2018-10-19 02:29:57746d6830521610127645f7e7c1a126edn/aGozi 54.39.81.123:443
2018-10-19 02:29:346c4b7fbbf0afa308f43b38ddf19d6598n/aGozi 54.39.81.123:443
2018-10-19 02:29:346c4b7fbbf0afa308f43b38ddf19d6598n/aGozi 54.39.81.123:443
2018-10-19 02:26:5592d835dde038bd5f8fcfa3f36619dfb3n/aGozi 54.39.81.123:443
2018-10-19 02:26:5592d835dde038bd5f8fcfa3f36619dfb3n/aGozi 54.39.81.123:443
2018-10-19 02:22:15d674360efac0d9a670d0accaca8281beVirustotal results 33/67 (49.25%) Gozi 54.39.81.123:443
2018-10-19 02:22:15d674360efac0d9a670d0accaca8281beVirustotal results 33/67 (49.25%) Gozi 54.39.81.123:443
2018-10-19 02:02:17bfa5ee0be84e61f432d6d6367b632ca3n/aGozi 54.39.81.123:443
2018-10-19 02:02:17bfa5ee0be84e61f432d6d6367b632ca3n/aGozi 54.39.81.123:443
2018-10-19 02:00:047d17ab3184c0b6ef04ca613f3060eaa3n/aGozi 54.39.81.123:443
2018-10-19 02:00:047d17ab3184c0b6ef04ca613f3060eaa3n/aGozi 54.39.81.123:443
2018-10-19 00:11:11819c2384edace44d7ac1acf1b8ae2a42n/aGozi 54.39.81.123:443
2018-10-19 00:11:11819c2384edace44d7ac1acf1b8ae2a42n/aGozi 54.39.81.123:443
2018-10-19 00:03:391f11eefa0dc1516f4c94b5659d215378n/aGozi 54.39.81.123:443
2018-10-19 00:03:391f11eefa0dc1516f4c94b5659d215378n/aGozi 54.39.81.123:443
2018-10-19 00:02:553ff08338d11b348ac11f4f04d4506a1cn/aGozi 54.39.81.123:443
2018-10-19 00:02:553ff08338d11b348ac11f4f04d4506a1cn/aGozi 54.39.81.123:443
2018-10-19 00:01:55a036d8092aac7dde91ce1fa323fdcdfaVirustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-19 00:01:55a036d8092aac7dde91ce1fa323fdcdfaVirustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-18 23:51:13ac1b627b41b9341dba98cb209dc39c46Virustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-18 23:51:13ac1b627b41b9341dba98cb209dc39c46Virustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-18 23:50:02ce74837888e299d2489e3f1ae921729dVirustotal results 34/68 (50.00%) Gozi 54.39.81.123:443
2018-10-18 23:50:02ce74837888e299d2489e3f1ae921729dVirustotal results 34/68 (50.00%) Gozi 54.39.81.123:443
2018-10-18 23:49:49622597650fdea1990e30ec5fb65ff1bcn/aGozi 54.39.81.123:443
2018-10-18 23:49:49622597650fdea1990e30ec5fb65ff1bcn/aGozi 54.39.81.123:443
2018-10-18 23:45:483a4f89fde8598e87598e5b2b8dce6747n/aGozi 54.39.81.123:443
2018-10-18 23:45:483a4f89fde8598e87598e5b2b8dce6747n/aGozi 54.39.81.123:443
2018-10-18 23:45:449803c2f9c8a26f78790065673656b028n/aGozi 54.39.81.123:443
2018-10-18 23:45:449803c2f9c8a26f78790065673656b028n/aGozi 54.39.81.123:443
2018-10-18 22:10:30086b5adf0e5bb619331189bb34b1b31dn/a54.39.81.123:443
2018-10-18 22:10:30086b5adf0e5bb619331189bb34b1b31dn/a54.39.81.123:443
2018-10-18 22:02:59597d9c66bdecebaed2cf88de9101132dn/aGozi 54.39.81.123:443
2018-10-18 22:02:59597d9c66bdecebaed2cf88de9101132dn/aGozi 54.39.81.123:443
2018-10-18 22:02:0760b1addfd673bb5694ef90ab170121b3n/aGozi 54.39.81.123:443
2018-10-18 22:02:0760b1addfd673bb5694ef90ab170121b3n/aGozi 54.39.81.123:443
2018-10-18 22:02:0543b427461bea91127430e72c6b3b95a7n/aGozi 54.39.81.123:443
2018-10-18 22:02:0543b427461bea91127430e72c6b3b95a7n/aGozi 54.39.81.123:443
2018-10-18 22:00:415ea197d038ba8a10aadd7e2e1951512an/aGozi 54.39.81.123:443
2018-10-18 22:00:415ea197d038ba8a10aadd7e2e1951512an/aGozi 54.39.81.123:443

# of entries: 100 (max: 100)